SAA-C03 Design Secure Architectures Practice Question
A company has a VPC with a CIDR block of 10.0.0.0/16. They need to allow an on-premises data center (192.168.0.0/24) to access a web application running on EC2 instances in a private subnet. The security team wants to ensure that only HTTP and HTTPS traffic from the on-premises network is allowed, and that the traffic is encrypted in transit. Which combination of AWS services should they use?
⚠ Common exam trap
The trap here is assuming that AWS Direct Connect encrypts traffic by default; it does not, and would require an additional VPN for encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up an AWS Site-to-Site VPN connection and configure security groups to allow HTTP/HTTPS from 192.168.0.0/24.
An AWS Site-to-Site VPN creates an encrypted tunnel between the on-premises network and the VPC, ensuring data in transit is protected. Security groups can then be configured to allow only HTTP and HTTPS traffic from the specific on-premises CIDR block, restricting access to the required ports. This combination satisfies both the encryption and traffic restriction requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set up an AWS Site-to-Site VPN connection and configure security groups to allow HTTP/HTTPS from 192.168.0.0/24.
Why this is correct
An AWS Site-to-Site VPN provides an encrypted tunnel over the internet between the on-premises network and the VPC. Security groups on the EC2 instances can be configured to allow inbound HTTP (port 80) and HTTPS (port 443) only from the on-premises CIDR. This meets the requirements for encryption in transit and restricted traffic.
- ✗
Set up an AWS Transit Gateway with a VPN attachment and configure security groups to allow all traffic from 192.168.0.0/24.
Why it's wrong here
A Transit Gateway with a VPN attachment provides encrypted connectivity, but the security group configuration allows all traffic, not just HTTP/HTTPS. This violates the requirement to allow only HTTP and HTTPS. Security groups should be restricted to the specific ports. Therefore, this option does not meet the requirement.
- ✗
Set up an AWS Client VPN endpoint and configure security groups to allow HTTP/HTTPS from the VPN client CIDR.
Why it's wrong here
AWS Client VPN is designed for individual remote users, not for connecting an entire on-premises network. It would require installing VPN client software on each device and does not provide a site-to-site connection. While it encrypts traffic, it is not the appropriate solution for connecting a data center network to a VPC. The requirement is for on-premises network access, not individual users.
- ✗
Set up an AWS Direct Connect connection and configure network ACLs to allow HTTP/HTTPS from 192.168.0.0/24.
Why it's wrong here
AWS Direct Connect provides a dedicated private network connection, but it does not encrypt traffic by default. While it can be combined with a VPN for encryption, the option as stated does not ensure encryption in transit. Additionally, network ACLs are stateless and less granular than security groups; they can allow traffic but do not provide the same stateful filtering. The requirement for encryption is not met with Direct Connect alone.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.